diff options
Diffstat (limited to 'custom/servers')
| -rw-r--r-- | custom/servers/apache.conf | 9 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| -rw-r--r-- | custom/servers/lighttpd.conf | 9 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| -rw-r--r-- | custom/servers/nginx.conf | 9 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
3 files changed, 12 insertions, 15 deletions
diff --git a/custom/servers/apache.conf b/custom/servers/apache.conf index bbd3e75..f25c444 100644 --- a/custom/servers/apache.conf +++ b/custom/servers/apache.conf @@ -205,11 +205,10 @@ AddType text/plain .txt # assets Apache serves. cgit itself sends only the headers the proxy # cannot supply. Those are Status, Content-Type, Content-Length and # Content-Disposition on downloads, Location on redirects, a no-store - # Cache-Control on unauthenticated responses, the auth filter's - # Set-Cookie, and on raw - # repository bytes a nosniff of its own next to the stricter policy - # "default-src 'none'". Everything else, this policy included, is the - # proxy's job. + # Cache-Control on unauthenticated responses, the auth filter's Set-Cookie, + # and on raw repository bytes a nosniff of its own next to the stricter + # policy "default-src 'none'". Everything else, this policy included, is + # the proxy's job. # # The word setifempty is load bearing on the two headers cgit can also # emit. "Header always set" replaces a same-named header even when the diff --git a/custom/servers/lighttpd.conf b/custom/servers/lighttpd.conf index 27c325d..c2a478f 100644 --- a/custom/servers/lighttpd.conf +++ b/custom/servers/lighttpd.conf @@ -76,11 +76,10 @@ $HTTP["host"] == "git.example.org" { # assets lighttpd serves. cgit itself sends only the headers the server # cannot supply. Those are Status, Content-Type, Content-Length and # Content-Disposition on downloads, Location on redirects, a no-store - # Cache-Control on unauthenticated responses, the auth filter's - # Set-Cookie, and on raw - # repository bytes a nosniff of its own next to the stricter policy - # "default-src 'none'". Everything else, this policy included, is the - # server's job. + # Cache-Control on unauthenticated responses, the auth filter's Set-Cookie, + # and on raw repository bytes a nosniff of its own next to the stricter + # policy "default-src 'none'". Everything else, this policy included, is + # the server's job. # # The add in add-response-header is load bearing. It appends a second # copy next to what cgit emitted, so a raw page carries both policies and diff --git a/custom/servers/nginx.conf b/custom/servers/nginx.conf index 3ffa2ba..7049368 100644 --- a/custom/servers/nginx.conf +++ b/custom/servers/nginx.conf @@ -154,11 +154,10 @@ http { # static assets nginx serves directly. cgit itself sends only the # headers the proxy cannot supply. Those are Status, Content-Type, # Content-Length and Content-Disposition on downloads, Location on - # redirects, a no-store Cache-Control on unauthenticated responses, - # the auth filter's - # Set-Cookie, and on raw repository bytes a nosniff of its own next to - # the stricter policy "default-src 'none'". Everything else, this - # policy included, is the proxy's job. + # redirects, a no-store Cache-Control on unauthenticated responses, the + # auth filter's Set-Cookie, and on raw repository bytes a nosniff of its + # own next to the stricter policy "default-src 'none'". Everything else, + # this policy included, is the proxy's job. # # add_header appends and never replaces what cgit sent, so a raw page # carries both policies and the browser enforces the stricter one, |
